Over The Wire – Bandit 21

Level Goal

A program is running automatically at regular intervals from cron, the time-based job scheduler. Look in /etc/cron.d/ for the configuration and see what command is being executed.

I started this challenge by trying to look at the crontab file itself but did not have much luck.

I then took the more obvious approach and looked in /etc/cron.d as the goal suggested.

Inside that directory, there are a couple different cronjob files.
catting cronjob_bandit22 shows us that there is a script in /usr/bin called cronjob_bandit22.sh that is being run.

Luckily, we have access to this directory, so we can just cat the file.

Doing so shows us that the password for bandit22 is being sent to a file in the  tmp directory.

catting this file gives us the flag

Screenshot from 2018-06-27 19-34-48.png

Leave a comment